What Is Right Fit For Risk (RFFR)? A Plain-English Guide
If your organisation delivers employment, skills, training or disability services under a Commonwealth contract, you have almost certainly come across the term Right Fit For Risk — usually abbreviated to RFFR. For many providers it surfaces as a contractual hurdle: something the Department expects, with a stack of templates attached and a deadline looming. But RFFR is more than a compliance checkbox. It is a structured assurance approach with a clear purpose, and understanding that purpose makes the work ahead far easier to scope.
This guide explains what RFFR is, who created it, why it exists, and what it is actually made of.
RFFR in one sentence
Right Fit For Risk (RFFR) is an information security accreditation approach developed by the Department of Employment and Workplace Relations (DEWR) — formerly the Department of Education, Skills and Employment (DESE) — that gives the Department assurance that contracted providers have the systems and processes in place to protect the confidentiality, integrity and availability of the Protected and sensitive information they handle on its behalf.
In short: when a provider holds government data outside the Department's own ICT environment, RFFR is how the Department satisfies itself that the data is being looked after properly.
Who developed RFFR — and the DEWR ISMS Scheme
RFFR was established by DESE in 2019 as part of the Department's broader External Systems Assurance Framework (ESAF) — the mechanism by which the Department gains assurance over systems and data sitting outside its direct control. When DESE became DEWR, the framework moved across with it.
Alongside the accreditation approach, an accredited certification scheme was introduced: the DEWR ISMS Scheme (originally the DESE ISMS Scheme). This is a formal scheme accredited by the Joint Accreditation System of Australia and New Zealand (JAS-ANZ). Its existence is what allows independent, accredited certification specifically tailored to the Department's requirements, rather than relying on a generic certificate alone.
Why RFFR exists
Employment services providers handle a great deal of sensitive personal information about job seekers, participants and employers. That information is valuable, and the consequences of mishandling it — to individuals and to public confidence — are serious.
RFFR exists to give the Department confidence that this information is protected wherever it lives. Rather than auditing every provider's environment itself, the Department relies on a risk-based, certifiable approach so it can make consistent, evidence-backed accreditation decisions. The "right fit for risk" name captures the underlying philosophy: the level of assurance expected is calibrated to the sensitivity of the information and the risk a provider's environment carries, not applied as a flat one-size-fits-all standard.
What RFFR is made of
This is where RFFR differs from a standard certification, and it is the part most worth understanding. RFFR is not a single standard — it is a composite of several elements stitched together:
- ISO/IEC 27001 certification. The internationally recognised standard for an Information Security Management System (ISMS) provides the management-system backbone — the structured, auditable way an organisation governs information security. The Workforce Australia Guidelines name the 2022 edition specifically, which is worth noting: some of the Department's older supporting material still refers to the 2013 edition's Annex A numbering.
- Australian Government ISM controls. The Australian Government's Information Security Manual (ISM) supplies the detailed, technical control set. RFFR draws applicable controls from the ISM and layers them on top of the ISO 27001 baseline, which is why an RFFR Statement of Applicability is considerably larger than a standard one.
- The Essential Eight. The Australian Cyber Security Centre's Essential Eight mitigation strategies are incorporated as a baseline of practical, high-impact cyber controls, with maturity assessed against the Essential Eight model. Maturity Level One is the Department's starting requirement — but it expects you to set a risk-based target of your own on top of it.
- Contractual principles. The fundamental requirements set out in the relevant Deeds, Grant Agreements, guidelines and other published departmental resources. These contractual expectations — including data sovereignty and personnel security — sit alongside the technical standards and are equally binding.
Put simply: ISO 27001 provides the system, the ISM provides the controls, the Essential Eight provides the cyber baseline, and the contract sets the expectations. RFFR is the framework that brings all four together.
Why only approved certification bodies can certify against it
Here is a point that trips up many providers. Because RFFR mandates the use of ISM-sourced controls — something a generic ISO 27001 certificate does not specifically validate — not every certification body can issue an RFFR-suitable certification.
Only Conformity Assessment Bodies (CABs) that are accredited by JAS-ANZ to certify against the DEWR ISMS Scheme can issue certifications under that scheme. The auditors must hold the relevant experience to verify the additional, more detailed ISM controls accurately. A provider on the standard ISO 27001 path can still meet RFFR requirements, but only if the certifying body is made aware that the Statement of Applicability contains ISM-sourced controls and audits accordingly. This is why selecting the right certification body early matters: not all of them can take you where you need to go.
Does RFFR apply to my organisation?
In broad terms, RFFR accreditation is a contractual requirement for providers delivering services under a DEWR Deed. The level of assessment scales with risk — driven largely by factors such as caseload and the sensitivity of the data handled — which is why providers fall into different categories with different obligations and milestones. Larger providers are generally required to attain independent certification, while smaller providers may follow a self-assessment route, with the same underlying expectations applying.
If you are unsure where your organisation sits, the starting point is your Deed and the Department's published accreditation resources, which set out the categories and the milestone deliverables that apply to each.
The bottom line
RFFR can look daunting from the outside — a tangle of standards, controls, templates and deadlines. But underneath, the logic is coherent: it is a risk-based assurance approach built on an ISO 27001 management system, hardened with Australian Government ISM controls and the Essential Eight, and bound by your contractual obligations to the Department.
Understanding that structure is the first step. The real work — scoping your ISMS, meeting the core expectations for personnel, physical and cyber security, running a live risk management process with real treatment plans, building a defensible Statement of Applicability against the current ISM, extending assurance across your subcontractors and supply chain, being able to respond to an incident when one arrives, proving the whole thing operates through internal audit and management review, and steering through the milestones — is where most of the effort lives, and where getting it right the first time saves enormous rework.
- DEWR — Right Fit For Risk accreditation
- ASD — Information Security Manual (ISM)
- ASD — Essential Eight
- ISO/IEC 27001 — Information security management
- JAS-ANZ — Joint Accreditation System of Australia and New Zealand
- JAS-ANZ Register — accredited bodies
External sources are provided for reference and are maintained by their respective bodies. Always confirm current requirements against the official source.
CHAIOS GRC Practitioner — Governance, risk & compliance
Written by a governance, risk and compliance practitioner on the CHAIOS team who has run RFFR and ISO 27001 programmes end to end — from risk registers and Statements of Applicability to DEWR accreditation. These guides come from hands-on experience, not theory.